New Slack certs rejected by PaloAlto PanOS firewalls

Slack emailed customers last week telling them they need to have X1 Root by May 9. This suggests (to me) that they had too many client systems that cannot handle the long-chain, and they've chosen to leave behind the EOL/EOS client devices? There's a convo about it here:

3 Likes